URLhaus Database

You are currently viewing the URLhaus database entry for https://91.92.42.46/sostener.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3854211
URL: https://91.92.42.46/sostener.vbs
URL Status:Offline
Host: 91.92.42.46
Date added:2026-05-27 20:25:06 UTC
Last online:2026-06-04 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2026-05-28 13:27:12 UTC to ripe{at}evro[dot]net)
Takedown time:7 days, 6 hours, 39 minutes Bad (down since 2026-06-04 20:06:58 UTC)
Tags:base64 Encoded opendir rat vbs

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-04sostener.vbsunknown d88151ec5ead2421be312d26da0176e1a4026e5e53f71fcb7cfdf423cbf46b50n/a 
2026-06-03sostener.vbsunknown 32b98d9b803649164b0ea7d073aac906714601883890c8b56e49dcdc2ab9338bn/a 
2026-05-29sostener.vbsunknown 0378e84dc99f5e952d28532ccae067a0f43aa4252d8acbde136d3058fbe93d5fn/a 
2026-05-29sostener.vbsunknown 799324db13d5a5bf049721cd04d015959ab6b58698a8935cf199a958dbf77bfan/a 
2026-05-28sostener.vbsunknown 560ebbc890717dc99be76a7fd4d36ec1d150c0f53a3c339fb267a178c8ca3584n/a